Vulnerability index

Browse CVEs

287 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

R8500 Firmware MEDIUM 5.7
CVE-2024-51003

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in th…

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-51004

Netgear R8500 v1.0.2.160 and R7000P v1.3.3.154 were discovered to multiple stack overflow vulnerabilities in the component usb_device.cgi via the cif…

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-51006

Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the ipv6_static_ip parameter in the ipv6_tunnel function. This vulnerability …

Mitigation only
Fix from $1,600 2024-11-05
Xr300 Firmware MEDIUM 5.7
CVE-2024-51007

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at wireless.cgi. This vulnerability allows attackers …

Mitigation only
Fix from $1,600 2024-11-05
Xr300 Firmware MEDIUM 5.7
CVE-2024-51011

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppo…

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware HIGH 8.0
CVE-2024-50993

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at admin_account.cgi. This vulnera…

Mitigation only
Fix from $1,950 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-50994

Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component ipv6_fix.cgi via the ipv6_wan_ipaddr, ipv…

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-50995

Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allow…

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-50996

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the bpa_server p…

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-50997

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip…

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-50998

Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component openvpn.cgi via the openvpn_service_port …

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-50999

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at password.cgi. This vulnerabilit…

Mitigation only
Fix from $1,600 2024-11-05
R7000 Firmware MEDIUM 6.8
CVE-2024-35520EPSS 9%

Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.

Mitigation only
Fix from $1,600 2024-10-14
Xr1000 Firmware HIGH 7.2
CVE-2024-35517EPSS 15%

Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.

Mitigation only
Fix from $1,950 2024-10-11
Dgn1000ww Firmware HIGH 8.8
CVE-2024-42756EPSS 14%

An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page

Mitigation only
Fix from $1,950 2024-08-23
Prosafe Network Management System HIGH 8.8
CVE-2024-6813

NETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers…

Mitigation only
Fix from $1,950 2024-08-21
Prosafe Network Management System HIGH 8.8
CVE-2024-6814

NETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacke…

Mitigation only
Fix from $1,950 2024-08-21
Wnr614 Firmware HIGH 8.8
CVE-2024-36787

An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspe…

No fix yet
Fix from $1,950 2024-06-07
Wnr614 Firmware HIGH 8.8
CVE-2024-36790

Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.

No fix yet
Fix from $1,950 2024-06-07
Wnr614 Firmware HIGH 8.2
CVE-2024-36792

An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.

No fix yet
Fix from $1,950 2024-06-07
Wnr614 Firmware HIGH 8.1
CVE-2024-36789

An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.

No fix yet
Fix from $1,950 2024-06-07
Prosafe Network Management Software 300 HIGH 8.8
CVE-2024-5246EPSS 31%

NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2024-05-23
R6850 Firmware CRITICAL 9.8
CVE-2024-30568EPSS 47%

Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.

No fix yet
Fix from $2,300 2024-04-03
R6850 Firmware HIGH 8.0
CVE-2024-30572

Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.

No fix yet
Fix from $1,950 2024-04-03
R6850 Firmware HIGH 7.5
CVE-2024-30569

An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication requ…

No fix yet
Fix from $1,950 2024-04-03
R6850 Firmware HIGH 7.5
CVE-2024-30571EPSS 14%

An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authenticat…

No fix yet
Fix from $1,950 2024-04-03
R6850 Firmware MEDIUM 5.3
CVE-2024-30570

An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

No fix yet
Fix from $1,600 2024-04-03
Dgnd4000 Firmware HIGH 8.8
CVE-2023-50677

An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi compon…

Mitigation only
Fix from $1,950 2024-03-14
Cbk40 Firmware HIGH 7.5
CVE-2024-28340

An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attacker…

No fix yet
Fix from $1,950 2024-03-12
Cbk40 Firmware MEDIUM 5.4
CVE-2024-28339

An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to …

No fix yet
Fix from $1,600 2024-03-12